首页> 外文OA文献 >Developers Need Support, Too:A Survey of Security Advice for Software Developers
【2h】

Developers Need Support, Too:A Survey of Security Advice for Software Developers

机译:开发人员也需要支持:针对软件开发人员的安全建议调查

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Increasingly developers are becoming aware of the importance of software security, as frequent high-profile se- curity incidents emphasize the need for secure code. Faced with this new problem, most developers will use their normal approach: web search. But are the resulting web resources useful and effective at promoting security in practice? Recent research has identified security problems arising from Q&A re- sources that help with specific secure-programming problems, but the web also contains many general resources that discuss security and secure programming more broadly, and to our knowledge few if any of these have been empirically evaluated. The continuing prevalence of security bugs suggests that this guidance ecosystem is not currently working well enough: either effective guidance is not available, or it is not reaching the developers who need it. This paper takes a first step toward understanding and improving this guidance ecosystem by identifying and analyzing 19 general advice resources. The results identify important gaps in the current ecosystem and provide a basis for future work evaluating existing resources and developing new ones to fill these gaps.
机译:开发人员越来越意识到软件安全的重要性,因为频繁发生的备受关注的安全事件强调了对安全代码的需求。面对这个新问题,大多数开发人员将使用他们的常规方法:网络搜索。但是,由此产生的Web资源对于在实践中提高安全性是否有用和有效?最近的研究已经确定了由问答资源引起的安全性问题,这些问题可帮助解决特定的安全编程问题,但是Web上也包含许多常规资源,可以更广泛地讨论安全性和安全编程,并且据我们所知,即使有经验证明,也很少。评估。安全漏洞的持续流行表明,该指南生态系统当前尚不能很好地发挥作用:有效的指南不可用,或者没有提供给需要它的开发人员。本文通过识别和分析19种一般建议资源,迈出了理解和改善该指导生态系统的第一步。结果确定了当前生态系统中的重要差距,并为未来工作评估现有资源并开发新资源以弥补这些差距提供了基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号